Hackers Leaked Personal Data of 3,615 Trump Mobile Customers
A breach involving a third-party partner exposed names, addresses, and order details of thousands of users.
Updated on Oct. 5, 2026 in Cybersecurity

Live Poll
Do you trust your current mobile carrier to protect your personal information from data breaches?
The hacker group BYOD released the personal information of 3,615 Trump Mobile customers on its dark web site last week. The exposed data includes names, email addresses, home addresses, and order details.
Why it matters
The breach highlights the risks posed by third-party vendor access, as attackers reportedly bypassed security by targeting an employee at Liberty Mobile. This exposure impacts a significant segment of the Trump Mobile user base.
The leak contains 3,615 records, including sensitive PII like home addresses and phone numbers. This affects a portion of the 590,000 customers who submitted $100 deposits for phones, though the total scale of the backend access remains unconfirmed.
The players
BYOD
A cybercrime group that specializes in dark web data distribution and enterprise system exploitation.
Trump Mobile
A telecommunications brand owned by T1 Mobile that focuses on the United States market.
Liberty Mobile
A Florida-based mobile services provider whose internal system served as the initial point of compromise.
Eric Brunnett
A vice president at the Trump Organization whose personal information was included in the data leak.
Nicholas Hayes
A lawyer for the Trump Organization based in Florida whose records were exposed in the breach.
The details
The attackers gained entry to corporate systems by infecting a Liberty Mobile employee with malware. This malicious software allowed the threat actors to pivot into the company's internal dashboard to extract customer records. The group then published these findings on a dark web leak site, claiming they had notified Trump Mobile of the vulnerability prior to the public release.
Timeline
Last week: The hacker group BYOD released customer data on its dark web site.
May 2026: Records indicated 590,000 customers had paid deposits for mobile phones.
The Tech Race
This incident follows a pattern of vendor-based compromise established by the 2020 SolarWinds supply chain attack. It underscores the critical challenge for mobile carriers in securing cross-organizational API and dashboard access.
Customers who paid $100 deposits for Trump Mobile hardware should monitor their personal email and financial accounts for potential phishing attempts. The leak includes physical home addresses and phone numbers, which may increase the risk of targeted social engineering.
The takeaway
This breach highlights the security vulnerabilities inherent in third-party vendor workflows. Users should watch for official security notifications from T1 Mobile to determine if their specific account data was compromised.
Further reading
Learn more about the latest developments in Cybersecurity.
Live Poll
Do you trust your current mobile carrier to protect your personal information from data breaches?









